Skip to content
84

Awesome Vulnerable Applications

Awesome Vulnerable Applications

1.5k stars229 forks99 entriesLast push Sep 24, 2026 (6 days ago)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Online

Hacker101 CTF

The Hacker101 CTF is a game designed to let you learn to hack in a safe, rewarding environment. Hacker101 is a free educational site for hackers.

In 2 lists

Web Security Academy

PortSwigger - A set of materials and labs to learn and exploit common web vulnerabilities.

In 4 listsDetails

Hack The Box

An online platform to test and advance your skills in penetration testing and cyber security. Join today and start training in our online labs.

In 7 listsDetails

Try Hack Me

TryHackMe is an online platform that teaches cyber security through short, gamified real-world labs.

In 7 listsDetails

CTFtime

Directory of upcoming and archive of past Capture The Flag (CTF) competitions with links to challenge writeups.

In 5 listsDetails

PWNABLE.KR

is a non-commercial wargame site which provides various pwn challenges regarding system exploitation.

In 4 lists

XSS game

A game about tricking people into running code in their browsers.

In 3 lists

Gin & Juice Shop

Duck Store

Pentest-Ground

Pentest-Tools.com - Pentest-Ground is a free playground with deliberately vulnerable web applications and network services.

In 4 lists

DVAIB

Damn Vulnerable AI Bank

OverTheWire: Wargames

Paid

PentesterLab

PentesterLab - Hands on labs to understand and exploit simple and advanced web vulnerabilities.

In 7 listsDetails

Vulnerable VMs

Vulhub

Pre-Built Vulnerable Environments Based on Docker-Compose

In 3 lists

Exploit Exercises

Variety of VMs to learn variety of computer security issues.

In 2 lists

Metasploitable3

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

Hackmyvm.eu

Cloud Security

Kubernetes Goat

Kubernetes Goat is "Vulnerable by Design" Kubernetes Cluster. Designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security.

In 3 lists

CloudGoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

In 3 lists

CdkGoat - Vulnerable AWS CDK Infra

CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository.

Cfngoat - Vulnerable Cloudformation Template

Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository.

In 2 lists

TerraGoat - Vulnerable Terraform Infra

TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository.

In 3 lists

caponeme - Capital One Breach

Repository demonstrating the Capital One breach on your AWS account

WrongSecrets

WrongSecrets is "Vulnerable by Design" to show how to not handle secrets in Docker, Kubernetes and in the cloud (AWS/GCP/Azure).

In 2 lists

AWSGoat

A Damn Vulnerable AWS Infrastructure

AzureGoat

A Damn Vulnerable Azure Infrastructure

In 2 lists

IAM Vulnerable

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

In 2 lists

Sadcloud

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

CNAPPgoat

CNAPPgoat is a multi-cloud, vulnerable-by-design environment deployment tool.

Unguard

An insecure cloud-native microservices demo application for Kubernetes

Vulnerable Cloud Lab

Intentionally vulnerable GCP and AWS infrastructure deployed with Terraform for authorized cloud security training.

SSO - Single Sign On

vulnerable-sso

vulnerable single sign on

Mobile Security

Allsafe

Allsafe is an intentionally vulnerable application that contains various vulnerabilities.

In 2 lists

InsecureBankv2

Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities.

In 3 lists

Vulnerable Kext

A WIP "Vulnerable by Design" kext for iOS/macOS to play & learn *OS kernel exploitation.

InjuredAndroid

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

In 2 lists

Damn Vulnerable Bank

Damn Vulnerable Bank is designed to be an intentionally vulnerable android application.

In 2 lists

InsecureShop

An Intentionally designed Vulnerable Android Application built in Kotlin.

In 2 lists

AndroGoat

AndroGoat is purposely developed open source vulnerable/insecure app using Kotlin.

DIVA Android

Damn Insecure and vulnerable App for Android.

In 3 lists

DVMA

Damn Vulnerable Mobile App, an intentionally vulnerable Flutter app for Android and iOS.

In 3 lists

OVAA

Oversecured Vulnerable Android App.

In 3 lists

Vuldroid

Android Application covering various static and dynamic vulnerabilities.

In 3 lists

Android Security Testing

hpAndro1337 Application made in Kotlin with multiple vulnerabilities and a CTF.

VulnLab APK

Intentionally vulnerable Android app covering OWASP Mobile Top 10 classes with exploit commands and screenshots.

OWASP Top 10

Owasp Juice shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

In 3 lists

crApi

completely ridiculous API: crAPI will help you to understand the ten most critical API security risks. crAPI is vulnerable by design, but you'll be able to safely run it to educate/train yourself.

In 2 lists

DVWA

Damn Vulnerable Web Application (DVWA)

In 3 lists

DSVW

Damn Small Vulnerable Web

In 3 lists

bWAPP

This is just an instance of the OWASP bWAPP project as a docker container.

Xtreme Vulnerable Web Application

XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.

In 2 lists

lazyweb

This web application is a demonstration of common server-side application flaws. Each of the vulnerabilities has its own difficulty rating.

OWASP Mutillidae II

OWASP Mutillidae II is a free, open source, deliberately vulnerable web-application providing a target for web-security enthusiast.

Pentest_lab

Local penetration testing lab using docker-compose.

VulnLab

A vulnerable web application lab using Docker

In 2 lists

WebGoat

WebGoat is a deliberately insecure application by OWASP for training purpose

In 3 lists

VAmPI

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

In 2 lists

OSS – OopsSec Store

An intentionally vulnerable e-commerce application built with Next.js and React. A self-hosted CTF platform for web security training covering OWASP Top 10 vulnerabilities.

In 4 listsDetails

Owasp VulnerableApp

A modular deliberately vulnerable application designed primarily for validating and benchmarking security scanners through reproducible test scenarios, while also supporting learning and experimentation.

In 2 lists

OWASP Top 10 >SQL Injection

Yet Another Vulnerability Database

Yet Another Vulnerability Database

OWASP Top 10 >XSS Injection

clicker-service - simulate XSS

Docker container that intakes post and then "clicks" the link. Intentionally vulnerable. To be used with vulnerable by design web apps to realistically simulate XSS and XSRF (CSRF).

XSSworm.dev

Self-replication contest

xssed

A set of XSS vulnerable PHP scripts for testing

xssable

A vulnerable blogging platform used to demonstrate XSS vulnerabilities.

OWASP Top 10 >Server Side Request Forgery

SSRF_Vulnerable_Lab

This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack

OWASP Top 10 >CORS Misconfiguration

CORS-vulnerable-Lab

Sample vulnerable code and its exploit code

CORS misconfiguration vulnerable Lab

This Repository contains CORS misconfiguration related vulnerable codes.

OWASP Top 10 >XXE Injection

XXE Lab

A simple web app with a XXE vulnerability.

docker-java-xxe

Docker image to test XXE attacks in java with tomcat.

OWASP Top 10 >Request Smuggling

Varnish HTTP/2 Request Smuggling

This repository a docker-compose file to setup a local environment that is vulnerable to CVE-2021-36740 Varnish HTTP/2 request smuggling.

Technologies >WordPress

DVWP

Damn Vulnerable WordPress

Technologies >.NET

The Most Vulnerable .NET App

Interactive educational project that demonstrates common security vulnerabilities in .NET applications

Technologies >Node.js

exploit-workshop

A step by step workshop to exploit various vulnerabilities in Node.js and Java applications

DVNA

Damn Vulnerable NodeJS Application

Extreme Vulnerable Node Application

Extreme Vulnerable Node Application

dvws-node

Damn Vulnerable Web Service is a vulnerable web service/API/application that can be used to learn webservices/API vulnerabilities.

In 2 lists

Technologies >Firmware

DVRF

The Damn Vulnerable Router Firmware Project

OWASP IoT Goat

IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices.

In 2 lists

DVID

Damn Vulnerable IoT Device

In 2 lists

Uncategorized

LogSnare

A playground for testing, preventing, and logging IDOR vulnerabilities.

GitHub Actions Goat

Deliberately Vulnerable GitHub Actions CI/CD Environment

dvws - Damn Vulnerable Web Services

Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities.

In 2 lists

Fuzzgoat

A vulnerable C program for testing fuzzers.

In 2 lists

wavsep

The Web Application Vulnerability Scanner Evaluation Project

leaky-repo

Benchmarking repo for secrets scanning

OWASP SKF labs

Repo for all the OWASP-SKF Docker lab examples

Vulnserver

Vulnerable server used for learning software exploitation

In 2 lists

Damn-Vulnerable-GraphQL-Application

Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.

In 2 lists

Vulnerable-nginx

An intentionally vulnerable NGINX setup

Raspwn OS

The intentionally vulnerable image for the Raspberry Pi.

python_security

This repository collects lists of security-relavent Python APIs, along with examples of exploits using those APIs

OWASP-VWAD

The OWASP Vulnerable Web Applications Directory project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.

Vulhub

Pre-Built Vulnerable Environments Based on Docker-Compose

In 3 lists

VulnDoge

Web app for hunters

CI/CD Goat

Deliberately vulnerable CI/CD environment. Hack CI/CD pipelines, catch the flags.

In 2 lists

Damn Vulnerable Thick Client

Damn Vulnerable Thick Client App developed in C# .NET

In 2 lists

Damn Vulnerable RESTaurant

Intentionally vulnerable Web API game for learning and training purposes dedicated to developers, ethical hackers and security engineers.

In 2 lists

VulnerableLightApp

.NET vulnerable REST API

OSTE-Vulnerable-Web-Application

Vulnerable Web application made with PHP/SQL designed to help new web testers gain some experience and test DAST tools for identifying web vulnerabilities.

Vulnerable AI Lab

Intentionally vulnerable AI agent lab for practicing RAG injection, tool misuse, memory poisoning, supply-chain compromise, and data exfiltration.

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed today
91

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k574 entriesPushed today
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago